Courseiva
Endpoint Security →mediumMultiple Select

GSEC Endpoint Security Practice Question

When configuring endpoint security, which THREE of the following are considered 'defense-in-depth' measures to protect against ransomware?

⚠ Common exam trap

Candidates sometimes select single-layer preventative solutions like basic password policies, missing that defense-in-depth requires multiple complementary layers spanning permissions, detection, and recovery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Applying the Principle of Least Privilege (PoLP) to user file shares.

Defense-in-depth requires multiple layers of security to ensure that if one control fails, others are present to mitigate the impact. For ransomware, this includes preventing the execution, limiting the scope of damage through permissions, and maintaining immutable backups. These layers ensure that an attacker must overcome multiple, diverse obstacles to achieve their objective of data encryption, significantly increasing the difficulty of a successful attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Applying the Principle of Least Privilege (PoLP) to user file shares.

    Why this is correct

    Limiting user permissions ensures that if a workstation is compromised, the attacker can only encrypt the files that user has permission to modify. This prevents the ransomware from spreading to critical shared network drives or sensitive directories, effectively containing the potential impact of the infection to a single user's profile.

  • ✗

    Disabling all network connections to the endpoint.

    Why it's wrong here

    Disabling all network connections makes the device non-functional in a modern business environment. While it stops ransomware from communicating, it is not a viable security strategy. Effective defense-in-depth relies on allowing necessary business traffic while inspecting and controlling that traffic, not simply severing all connectivity to the network.

  • ✓

    Utilizing offline or immutable backups.

    Why this is correct

    Backups are the final line of defense against ransomware. Immutable backups cannot be modified or deleted by the ransomware, ensuring that data can be restored even if the primary systems are fully compromised. This allows organizations to recover without paying the ransom, neutralizing the attacker's primary leverage.

  • ✓

    Deploying Endpoint Detection and Response (EDR) with behavioral blocking.

    Why this is correct

    EDR agents monitor for ransomware behavior, such as rapid file renaming and entropy changes. By detecting these patterns in real-time, the agent can automatically kill the malicious process and isolate the host before the encryption process completes, providing a critical layer of automated response against novel malware variants.

  • ✗

    Enabling guest access for easier file sharing across departments.

    Why it's wrong here

    Enabling guest access increases the attack surface and allows unauthorized users to access resources. This is the opposite of good security hygiene, as it provides a path for ransomware to traverse the network more easily. Security controls should focus on restricting access, not facilitating open access across departments.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.